Описание
Cross-site scripting (XSS) vulnerability in e107_admin/filemanager.php in e107 1.0.4 allows remote attackers to inject arbitrary web script or HTML via the e107_files/ file path in the QUERY_STRING.
Ссылки
- ExploitThird Party AdvisoryVDB Entry
- ExploitMitigationThird Party Advisory
- Not Applicable
- Not Applicable
- Mailing ListThird Party Advisory
- Third Party AdvisoryVDB Entry
- Issue TrackingThird Party Advisory
- ExploitThird Party AdvisoryVDB Entry
- ExploitMitigationThird Party Advisory
- Not Applicable
- Not Applicable
- Mailing ListThird Party Advisory
- Third Party AdvisoryVDB Entry
- Issue TrackingThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:e107:e107:1.0.4:*:*:*:*:*:*:*
EPSS
Процентиль: 74%
0.00796
Низкий
4.3 Medium
CVSS2
Дефекты
CWE-79
Связанные уязвимости
github
больше 3 лет назад
Cross-site scripting (XSS) vulnerability in e107_admin/filemanager.php in e107 1.0.4 allows remote attackers to inject arbitrary web script or HTML via the e107_files/ file path in the QUERY_STRING.
EPSS
Процентиль: 74%
0.00796
Низкий
4.3 Medium
CVSS2
Дефекты
CWE-79